Frequently asked questions
Who sees what, how entries are protected, what happens when someone leaves, moving over from another password manager and what it costs.
The questions we get asked most often about the credentials vault. If you are looking at an error message, a forgotten master password or an entry you cannot see, the answer is under Troubleshooting.
Does the vault cost credits?
No. It is a standard tool, pre-installed on every plan, and it uses no credits. Share links, the vault check and emergency access cost nothing either. Details: Cost and availability.
Who can see an entry?
Only whoever it is shared with. Sharing happens per entry, to individual members, to roles or to groups. Without a grant an entry does not appear in the list at all, and not in search either.
Can admins see my personal entries?
No. Entries with the visibility personal are visible only to whoever created them, explicitly not to admins. The only technical exception is the owner of the workspace.
How are entries protected?
Every secret is encrypted before it touches the database. On the highest level the encryption already happens in your browser, with your personal master password, so the server never sees the plain text. Search only covers title, address, username and tags, never the secret itself.
Do I need a master password to use the vault?
No. The master password is only needed for entries on the hyper-sensitive level. Standard and sensitive entries work entirely without it.
What happens if I lose my master password?
Hyper-sensitive entries then stay unreadable for good, for us as well. That is precisely the point of this level, which is why the warning appears while you set it up. Standard and sensitive entries are unaffected.
Does the vault lock itself again?
Yes. An unlocked vault session expires after the configured time, and on inactivity the vault locks itself on top of that. Both are set as a team policy, see Security.
Does the platform email external share links?
No. An external link is shown to you exactly once, you copy it and send it yourself. That keeps you in control of the delivery route. Every link has an expiry date, can be revoked at any time, and every retrieval is counted and logged.
Can I bring my passwords over from another manager?
Yes. The import reads CSV files from browsers, 1Password, Bitwarden or Excel. The file is only read inside your browser, and duplicates are detected by the import itself. Guide: Managing entries.
What happens when someone leaves the office?
You revoke the grants in one place instead of ten. The when someone leaves area of the vault check additionally shows which credentials need rotating, records what that person last had access to, and can be exported as a list.
Can I tell who opened a credential?
Yes. Every view, copy, change and share is recorded in the access log, on the sensitive level together with the stated reason. Secrets themselves never appear there. The log is cleaned up automatically after twelve months.
What happens to my entries if I uninstall the tool?
Nothing. Uninstalling keeps all data. Actually deleting it is a separate, explicit step.
Related#
The confidentiality levels in detail: Security. What the tool costs: Cost and availability. Back to the overview.